The sig is intended to identify SSL traffic on unexpected ports. There are a set of sigs before this that will unset the flowbit for EXPECTED common SSL ports. You can add a similar sig for this port's traffic and you should be good to go.